FAIL › dossier
Network Attached Storage (NAS)
PRODUCT· dossier confidence 20%
QNAP is a NAS vendor with a documented history of critical vulnerabilities in File Station and HBS 3 services that were actively exploited in ransomware attacks.
PROFILE
CategoryNASWhat they doQNAP develops and sells network-attached storage (NAS) devices and solutions for desktop, notebook, and enterprise environments.
Websitehttps://www.qnap.com ↗
SECURITY POSTURE
QNAP has a history of critical vulnerabilities in its File Station and HBS 3 services, including RCE and XSS flaws that were actively exploited in ransomware attacks.
Notable failures
- CVE-2018-19949: Critical RCE in File Station
- CVE-2018-19953: Critical XSS in File Station
- CVE-2018-19943: Critical XSS in File Station
- CVE-2021-28799: Critical RCE in HBS 3
Patterns: Repeated critical RCE vulnerabilities in File Station; XSS vulnerabilities enabling ransomware attacks; Improper authorization in HBS 3 service
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-05-24 | CVE-2018-19949 | critical | QNAP NAS File Station suffered a critical command injection flaw that allowed remote attackers to execute arbitrary commands, directly enabling ransomware attacks. |
| 2022-05-24 | CVE-2018-19953 | critical | QNAP NAS File Station XSS vulnerability allowed remote attackers to inject malicious code, linked to ransomware attacks. |
| 2022-05-24 | CVE-2018-19943 | critical | QNAP NAS devices were vulnerable to cross-site scripting, exploited in the wild, and linked to ransomware activity. |
| 2022-03-31 | CVE-2021-28799 | critical | QNAP NAS devices with HBS 3 allowed unauthorized remote logins due to an improper authorization vulnerability, actively exploited in ransomware attacks. |
DOSSIER SOURCES
- Sandisk (SNDK) Company Profile & Description - Stock Analysis · stockanalysis.com
Open questions: Current patch status of affected QNAP devices · Recent security posture improvements post-2022
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:45:13.720422+00:00